Authentication · QAuth

Authentication that keeps
good customers moving.

ACS, risk-based authentication, passkeys and in-app approval — layered strong customer authentication that keeps good customers moving. One platform for every authentication moment — from card-not-present challenges to login step-up — tuned so friction lands only where the risk actually is.

90%+
Silent authentications
4
Challenge channels
<3s
Typical approval time
0
Passwords required
Capabilities

Every layer of strong customer authentication.

One platform for the full SCA surface — issuer ACS, risk-based scoring, passkeys, in-app approval and OTP fallback — governed by a single step-up policy engine.

Access Control Server

A full issuer-side ACS that answers 3-D Secure authentication requests for your card portfolio, with per-BIN policy control and scheme-compliant messaging.

Risk-based authentication

Score each authentication on device, behaviour, velocity and transaction context. Authenticate the safe majority silently and reserve challenges for genuine anomalies.

Passkeys & FIDO2

Phishing-resistant passwordless credentials bound to the customer's device. One biometric touch replaces OTPs — stronger security with dramatically less abandonment.

In-app approval

Push a rich approval prompt to your banking app showing merchant, amount and currency. The customer confirms with a fingerprint; the transaction proceeds in seconds.

OTP fallback channels

SMS, email and voice one-time passcodes with rate limiting and delivery failover — dependable coverage for customers without smartphones or app installs.

Step-up policy engine

Compose layered policies: silent for trusted devices, passkey for new ones, in-app approval above a threshold. Change policy in the dashboard, not in a release cycle.

Risk-based by default

Challenge the risk, not the customer.

QAuth scores every authentication on device, behaviour, velocity and transaction context, then lets the safe majority through silently. Genuine anomalies get a step-up — everyone else keeps moving.

  • Signals, not frictionDevice, geo, velocity and behavioural context decide the path before a customer ever sees a prompt.
  • Exemptions applied automaticallyTRA, low-value and trusted-beneficiary exemptions used where scope allows, with clean fallback to challenge.
  • Tuned from the dashboardAdjust thresholds and channels live — no release cycle to change how customers are authenticated.
Passwordless, phishing-resistant

Passkeys and in-app approval replace the OTP treadmill.

Bind credentials to the customer's hardware and swap one-time codes for a single biometric touch — stronger security with far less abandonment.

FIDO2 passkeysOne touch replaces OTPs
Rich in-app promptsMerchant, amount and currency shown
Device bindingStolen OTPs and replays can't stand in
OTP failoverSMS, email and voice for every customer
How it works

The right challenge, at the right moment.

Event arrives

A payment, login or sensitive action triggers an authentication request into QAuth with full context attached.

Risk engine decides

Your policy and the risk score choose the path: silent pass, passkey, in-app approval or OTP fallback.

Signed result returned

QAuth returns a verifiable authentication result your systems — and the card schemes — can trust and audit.

One API call

Start an authentication in a single request.

Send the transaction context; QAuth evaluates policy and risk, then tells you whether to proceed silently or which challenge to render. Every decision returns a signed, verifiable result.

EMV 3-D Secure 2.x FIDO2 / WebAuthn PSD2 SCA
POST /api/v1/qauth/authenticate Authorization: Bearer sk_live_••••• { "reference": "auth_9f2c17", "amount": 480000, "currency": "NGN", "channel": "card_not_present", "device": { "id": "d_8821", "trusted": true } } 200 OK { "decision": "frictionless", "method": "risk_based", "result_token": "arq_5b1e…", "signed": true }
Built in

The controls that keep SCA compliant and low-friction.

Exemptions, delegated authentication and full auditability — configured once and enforced everywhere issuers and PSD2/SCA programmes rely on them.

SCA exemption handlingApply TRA, low-value and trusted-beneficiary exemptions automatically, with fallback to challenge when scope is exhausted.
Scheme-certified ACS3-D Secure 2.x messaging certified against the major card networks, with per-BIN and per-region routing.
Device bindingBind passkeys and app credentials to hardware so a stolen OTP or replayed session can't stand in for the customer.
Delegated authenticationLet trusted merchants and wallets authenticate on your behalf under policies you define and can revoke instantly.
Signed, auditable resultsEvery decision returns a verifiable authentication result with the evidence trail regulators and schemes expect.
Dashboard-driven policyTune thresholds, channels and challenge rules from the console — no release cycle to change how customers are authenticated.
Modernise SCA

Retire the OTP treadmill.

Migrate your portfolio to risk-based, passkey-first customer authentication — silent for the safe majority, strong where it counts.